1. Do you agree or disagree with the author's assertions regarding
seasonal employees and cybersecurity risks in the workplace?
Why?
First, all companies today must think about how to secure their
system. I agree with the author's assertion on protecting
companies' systems. The idea is to hire new workers and train
these employees on the company's security system and how they
can watch the company's system from being attacked. Seasonal
employees are those who come to a company for a bit of time. It
can be during holidays, peak season, or a period of need. The
author claims that "As noted by CPA Practice Advisor, companies
experience a 20 percent fraud increase over the holiday season,
in part thanks to existing employees who seize the opportunity
and in part due to the influx of seasonal workers (Bonderud,
2016)". If this is the case, companies have the responsibility to
increase the level of protection in their companies. However,
companies are always vulnerable to cyber attacks, but this is a
specific situation where there is mass employment, and the
companies might not take in consideration the total control and
protection of the system. When this happens, the system
becomes exposed to attacks. The author gave some tips on how
companies should protect their system when hiring seasonal
employees. He talks of implementing a solid onboarding and
integration process.
2. What steps can (should) managers take to reduce security risks
associated with hiring seasonal or temporary employees?
(Consider whether or not the Secure Computer User training
course would be appropriate for these employees.)
Managers can take many steps to reduce security risks
associated with seasonal or temporal employees. Douglas
Bonderud, in his article, gave some steps on how to mitigate the
situation. However, providing employees with a secure computer
user training course will be more advantageous. It is crucial
because seasonal or temporal employees are traine on how the
company’s system functions and be aware of the consequences to
bridge or violate the policies or guidelines of the company. This
training will give employees the knowledge on how to secure
data, the importance of data in the information, elements of
security, and many other things necessary to ensure the system is
secured. This training will give employees a broad knowledge of
cyber security and how they must be responsible for preventing
attacks due to vulnerabilities. For example, many hotels hire
customer service, concierge, and room assistance for season
employment, and most of them have access to the hotel company
and much other information. In this regard, the manager has the
responsibility to train these seasonal employees on the privacy or
policies of the hotel to prevent cyber-attack. The process of
onboarding must be the same as temporal employees. Douglass
said in his article, “It’s important to keep hiring practices
consistent. Don’t change the interview, vetting process or
background check requirements for new workers simply because
they aren’t full-time employees (Bonderud, 2016)”.
3. How can managers show leadership in the area of
cybersecurity defenses and best practices?
First, managers must receive cybersecurity training. Some
managers are not trained in the domain of cybersecurity and
hence are not able to transfer the knowledge to employees. Also,
managers must be educated on the importance of cybersecurity in
small businesses. Most managers neglect this aspect because they
think they are not exposed to cyber-attacks due to the small size
of their business. Hackers attack whenever there is a vulnerability
in the system; it doesn't if it is a small, medium, or large business.
Douglass said in his article, "Of course, hiring the right people is
only half the battle. Once workers are familiar with expectations
and their environment, companies need to train them in specific
work tasks" (Bonderud, 2016).